Privacy
Privacy Policy
1. Who we are (Controller)
The controller responsible for the processing of personal data described in this policy is:
Luann de Carvalho Sapucaia, trading as „Ephyra“
Ringbahnstraße 56, 12099 Berlin, Germany
Email: contact@ephyra.tech
We have not appointed a Data Protection Officer, as we are not legally required to do so under Art. 37 GDPR / § 38 BDSG. For any privacy matter, contact us at the email address above. Our full legal disclosure is available in our Impressum.
2. What Ephyra does, in data terms
Ephyra is an automated security-scanning product. When you run a scan, you connect a GitHub repository with read-only access. Ephyra reads the repository source code, runs deterministic checks across the file set, and returns a ranked security report.The working copy of your code is discarded after the scan completes or fails; only the resulting report is retained. Reports may contain repository file paths and relevant redacted code excerpts needed to explain findings. Usable detected credential values are not intentionally retained in report fields. There is no human review of your code as part of the automated product.
3. Categories of data we process
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, password (stored only as a salted hash), display name. | You, at sign-up. |
| Authentication / connection data | GitHub account identifier and OAuth access tokens used to read repositories you authorise. | You, via GitHub OAuth. |
| Scan input | The identifier and contents of the GitHub repository you authorise us to read. This may incidentally include secrets, API keys, or personal data present in your codebase. | You, when starting a scan. |
| Scan output | The security report: findings, severities, repository file/line locations, suggested fixes, and relevant redacted code excerpts. Usable detected credential values are not intentionally retained in report fields. | Generated by Ephyra. |
| Payment data | Billing details and transaction records. Card data is handled directly by our payment processor; we do not store full card numbers. | You / Stripe. |
| Technical & usage data | IP address, browser/device metadata, log and diagnostic data, scan timestamps. | Collected automatically. |
4. Why we process it, and on what legal basis
- To provide the service — creating your account, running scans, returning reports. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- To take payment — processing one-time and subscription charges. Legal basis: Art. 6(1)(b) GDPR; retention of invoices is a legal obligation, Art. 6(1)(c) GDPR.
- To secure and improve the product — abuse prevention, debugging, aggregate analytics. Legal basis: our legitimate interests, Art. 6(1)(f) GDPR, balanced against your rights.
- To communicate with you — service messages and support. Legal basis: Art. 6(1)(b) and (f) GDPR. Marketing email, if any, is sent only with your consent, Art. 6(1)(a) GDPR, and can be withdrawn at any time.
- To comply with the law — tax, accounting, and lawful requests. Legal basis: Art. 6(1)(c) GDPR.
5. The code you submit
We treat scan input as confidential. We access only what you authorise, use it solely to produce your report, and delete the cloned working copy once the scan finishes or fails. The retained report may contain repository file paths and relevant redacted code excerpts needed to explain findings; usable detected credential values are not intentionally retained in report fields. We do not use your source code to train any machine-learning model, and we do not sell it. Where your code contains personal data of third parties, you act as the controller for that data and Ephyra processes it on your behalf; in that case our Terms of Service and, where required, a separate data processing agreement (Art. 28 GDPR) govern that processing. Contact us at contact@ephyra.tech to put a DPA in place.
6. How long we keep data
- Cloned source code (working copy): deleted automatically after the scan completes or fails; not retained.
- Scan reports: kept for as long as your account is active, so you can revisit them, and deleted on account closure (subject to the legal retention below). Reports may retain repository file paths and relevant redacted code excerpts, but usable detected credential values are not intentionally retained in report fields.
- Account data: kept until you delete your account or ask us to erase it.
- Invoices and payment records: retained for up to 10 years to meet German commercial and tax-law obligations (§ 147 AO, § 257 HGB).
- Server logs: retained for a short period for security and then deleted or anonymised.
7. Who we share data with (processors)
We use carefully selected service providers who process data on our behalf under Art. 28 GDPR data processing agreements. We do not sell personal data. Our current sub-processors are:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Authentication and database (account data, scan reports). | EU (eu-central-1, Frankfurt) |
| Stripe | Payment processing and billing. | EU / USA |
| GitHub (Microsoft) | OAuth sign-in and repository access. | USA |
| DeepSeek (DeepSeek V4 Flash) | AI analysis of submitted code and app data. | China |
| Railway | Hosting — running the application and background scan workers. | EU-West (Amsterdam) |
| Resend | Transactional email delivery (scan notifications, purchase confirmations). | USA |
| Sentry (Functional Software, Inc.) | Error monitoring and diagnostics (IP addresses, technical event data). | USA |
| Contentsquare (Contentsquare S.A.S.) | Session replay and heatmaps on the public marketing site, loaded only after the visitor accepts the analytics category in the consent banner (see § 10). | EU / global CDN |
We may also disclose data where required by law, to enforce our terms, or to protect the rights, property, or safety of Ephyra, our users, or others.
8. International transfers
Some processing — in particular AI analysis via DeepSeek (DeepSeek V4 Flash) — occurs outside the EU/EEA, in countries without an EU adequacy decision (China, and the USA for Stripe, GitHub, Resend, and Sentry — the latter two receiving only email addresses and technical diagnostic data respectively).
What this does — and does not — involve. We do not share your account details, login credentials, or payment information with the AI provider. The only thing sent to it is the source code from the GitHub repository you authorise for a scan; it is used solely to generate your report, is not used to train any AI model, and the working copy is deleted once the scan completes (see §5). Because that material is your own code, it may incidentally contain personal data or secrets you have placed there — which is why this transfer is covered here.
Where personal data is transferred to a third country, we rely on appropriate safeguards under Chapter V GDPR — an EU adequacy decision where one exists, or the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with supplementary measures. You can request a copy of the relevant safeguards by contacting us. If you do not wish your code to be processed by a non-EU AI provider, do not submit scans, or contact us to discuss available options.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on legitimate interests (Art. 21); and
- withdraw consent at any time, without affecting prior lawful processing (Art. 7(3)).
To exercise any of these rights, email contact@ephyra.tech. You also have the right to lodge a complaint with a supervisory authority. The authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), but you may contact any EU supervisory authority.
10. Cookies and tracking
We use only the cookies and local storage strictly necessary to run the service — for example to keep you signed in. These do not require consent under § 25(2) TDDDG.
In addition, with your prior consent we load the following non-essential trackers on the marketing site (ephyra.tech). They help us understand how the product is used so we can fix friction and improve it. They are not loaded until you accept the analytics category in our consent banner, and you can withdraw consent at any time.
| Tracker | Provider | Purpose | Region |
|---|---|---|---|
| Contentsquare UXA (session replay, heatmaps) | Contentsquare S.A.S. (also known as Hotjar in earlier integrations) | Records anonymised sessions of how you interact with the site so we can replay them, generate heatmaps, and find usability issues. The tag loads only after you accept analytics in the consent banner. | EU / global CDN |
| Google Analytics 4 (reserved) | Google Ireland Ltd. | Aggregate page-view and event analytics. Not loaded today — reserved under the same analytics consent category; this policy will be updated before activation. | EU / USA |
| Sentry client-side (reserved) | Functional Software, Inc. | Front-end error monitoring. Not loaded today— our Sentry integration is currently server-side only (§ 7). When a client-side Sentry SDK is added it will attach to the same analytics consent category. | USA |
How consent works. On your first visit a banner asks you to Accept or Reject analytics tracking. Reject is as easy as accept — both are equal-weight buttons. Your choice is stored in a first-party cookie named cc_ephyra for 180 days and is applied on every subsequent visit; you will not be re-prompted unless you clear your cookies, the consent record expires, or you reopen the preferences from the “Cookie settings” link in the site footer. If you reject — or close the banner without choosing — none of the trackers above are loaded and no beacon, pixel, or analytics request is made. You can change your choice at any time via that footer link, which reopens the consent preferences where you can switch the analytics category on or off. Withdrawing consent removes the Contentsquare tag from the page and clears any related cookies.
For the legal basis for processing under § 25 TDDDG and Art. 6(1)(a) GDPR (consent) and Art. 6(1)(f) GDPR (legitimate interests, where applicable), see § 4.
11. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and prompt deletion of cloned source code after each scan. No method of transmission or storage is completely secure, but we work to protect your data and to address vulnerabilities responsibly.
12. Children
Ephyra is intended for businesses and professional developers and is not directed at children. We do not knowingly collect personal data from anyone under 16.
13. Changes to this policy
We may update this policy as the product or the law evolves. We will post the revised version here and update the “last updated” date; material changes will be communicated to account holders where appropriate.
Questions about this policy or your data? Email contact@ephyra.tech.